Impact
Apache Syncope 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, 4.1.0-M0 through 4.1.2 contain an improper code generation flaw (CWE-94). An administrator with sufficient privileges can create a Groovy Command class whose static CommandArgs implementation contains untrusted code that bypasses the Groovy security sandbox, thereby allowing arbitrary code execution within the Syncope application context. This flaw compromises the integrity and confidentiality of the system by enabling attackers to run injected code.
Affected Systems
Affected vendors and products include Apache Software Foundation’s Syncope. The vulnerability spans Syncope releases from 3.0.0-M0 up to 3.0.16, from 4.0.0-M0 through 4.0.7, and from 4.1.0-M0 through 4.1.2. Any installation using a version in these ranges is at risk unless updated.
Risk and Exploitability
Exploitation requires the attacker to have administrative privileges that allow creation or modification of Command classes, or they must compromise such credentials. The attack vector is inferred to be an insider or compromised-admin scenario. No CVSS or EPSS score is currently available, and the vulnerability is not listed in the CISA KEV catalog. Consequently, the risk remains significant for systems where administrative roles are broad or where credentials are not adequately protected.
OpenCVE Enrichment